CVE-2021-3541
Published: 18 May 2021
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
Notes
Author | Note |
---|---|
avital | Not reproducible in 2.9.4+dfsg1-6.1 and prior |
Priority
CVSS 3 base score: 6.5
Status
Package | Release | Status |
---|---|---|
libxml2 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Released
(2.9.10+dfsg-5ubuntu0.20.04.1)
|
|
groovy |
Released
(2.9.10+dfsg-5ubuntu0.20.10.2)
|
|
hirsute |
Released
(2.9.10+dfsg-6.3ubuntu0.1)
|
|
impish |
Not vulnerable
(2.9.10+dfsg-6.7)
|
|
jammy |
Not vulnerable
(2.9.10+dfsg-6.7)
|
|
precise |
Ignored
(end of ESM support, was needs-triage)
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Released
(2.9.10+dfsg-6.7, 2.9.11)
|
|
xenial |
Not vulnerable
(code not present)
|
|
Patches: upstream: https://gitlab.gnome.org/GNOME/libxml2/-/commit/8598060bacada41a0eb09d95c97744ff4e428f8e |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3541
- https://bugzilla.redhat.com/show_bug.cgi?id=1950515
- https://gitlab.gnome.org/GNOME/libxml2/-/commit/8598060bacada41a0eb09d95c97744ff4e428f8e
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/228 (currently private)
- https://blog.hartwork.org/posts/cve-2021-3541-parameter-laughs-fixed-in-libxml2-2-9-11/
- https://ubuntu.com/security/notices/USN-4991-1
- NVD
- Launchpad
- Debian